4 ms·
The "huge swaths of the internet" part is poorly phrased in the article. What they're basically saying is that there are a large number of DNS servers on the In
by imbriaco 13y ago
The "huge swaths of the internet" part is poorly phrased in the article. What they're basically saying is that there are a large number of DNS servers on the Internet that allow anyone to query them. Attackers query those servers and forge the source address that the query originates from such that it points at the IP address of their target. The attacker needs only send 36 bytes of data to the DNS server and the server responds with up to thousands of bytes of response -- directly at the target of the attack.
I don't know precisely how CloudFlare mitigated it but I can make some guesses:
- They may have just blocked UDP traffic on their edge. Since their DDoS mitigation service is specifically for HTTP and HTTPS, UDP is safe to simply drop.
- They may have determined that the attack responses had payloads that fell within a size range, and configured their mitigation hardware or routers to drop packets in that size envelope.
- They may have analyzed inbound UDP traffic to see what open resolvers were flooding them and surgically blocked UDP traffic from those IPs.